利用数学方法保护机密数据
文章来源:未知 文章作者:enread 发布时间:2011-12-19 06:15 字体: [ ]  进入论坛
(单词翻译:双击或拖选)

Statistical1 databases (SDBs) are collections of data that are used to gather and analyze2 information from a variety of sources. The data may be derived3 from sales transactions(处理) , customer files, voter registrations4, medical records, employee rosters5, product inventories6, or other compilations7 of facts and figures. Because database security requires multiple processes and controls, it presents huge security challenges to organizations. With the computerization of databases in healthcare, forensics(辩论术) , telecommunications, and other fields, ensuring this kind of security has become increasingly important.

In a paper recently published in the SIAM Journal on Discrete8 Mathematics, authors Rudolf Ahlswede and Harout Aydinian analyze a security-control model for statistical databases.

"Providing privacy and confidentiality10 in SDBs is not a new issue," Aydinian points out. "Privacy interests have evolved from the very first census11 in the United States. Recorded protests until the mid-20th century reflect constitutional issues resulting from the requirement for U.S. residents to provide sensitive personal information. Questions on census forms about diseases, mortgage values, and other items have raised many concerns."

While such databases are very helpful in aggregating12 data, there is a risk that confidential9 information about an individual's record may be deliberately13(故意地) compromised. "Since such data sets also contain sensitive information, such as the disease of an individual, or the salary of an employee, it is necessary to provide security against the disclosure of confidential information," says Aydinian. "Even in cases where a user has no direct access to sensitive information, sometimes confidential data about an individual can be inferred by correlating enough statistics."

Typically, statistical databases are designed to only accept queries14 that involve specific statistical functions (such as sum, average, count, min, max, etc.). However, the use of these queries may render databases susceptible15 to compromise. For instance, it may be possible to infer information about specific individuals by putting together data from a sequence of statistical queries, using prior knowledge of an individual, or through collusion among users.

An SDB is considered secure if no protected data can be inferred from available queries. "In the literature, many scenarios16 of compromise and inference control methods have been proposed to protect SDBs," Aydinian says. "However, to date no one security control method is capable of completely preventing compromise."

Query17 restriction18 is one of several general approaches used for security control. A "query request" retrieves19 a subset(子集) of data from a database that meets a set of conditions. In query restriction, the kind and amount of data that can be retrieved20 by such queries is limited, for example, the size of the data, or the amount of overlap21 between data that is returned.

In one type of query restriction method, only certain sums of individual records (called "SUM queries") that meet a minimum specified22 size or number, and satisfy a specified set of conditions, are available to users.

Aydinian explains with an example. "Consider a company with a large number of employees. Suppose that for each member of the company, the sex, age, rank, length of employment, salary etc. is recorded. The salaries of individual employees are confidential. Suppose that only SUM queries are allowed, i.e. the sum of the salaries of the specified people is returned. Then one might pose the query: What is the sum of salaries for males, above 50, and during the last 10 years?"

The task addressed in the paper is to provide an optimal23 collection of SUM queries that prevents compromise of confidential information -- such as individual salaries, for instance. A natural solution is to maximize the number of available SUM queries. The authors obtain tight bounds for the maximum number of such queries that return subsets of data without compromising groups of entries.

"Future work in the query-restriction approach includes evaluation25 of new security-control mechanisms26, which are easy to implement27 and guarantee absolute security," says Aydinian. "At the same time, it is desirable that these methods satisfy other criteria28 like richness of available queries, consistency29, cost etc. It also seems promising24 to develop methods combining different security control mechanisms."



点击收听单词发音收听单词发音  

1 statistical bu3wa     
adj.统计的,统计学的
参考例句:
  • He showed the price fluctuations in a statistical table.他用统计表显示价格的波动。
  • They're making detailed statistical analysis.他们正在做具体的统计分析。
2 analyze RwUzm     
vt.分析,解析 (=analyse)
参考例句:
  • We should analyze the cause and effect of this event.我们应该分析这场事变的因果。
  • The teacher tried to analyze the cause of our failure.老师设法分析我们失败的原因。
3 derived 6cddb7353e699051a384686b6b3ff1e2     
vi.起源;由来;衍生;导出v.得到( derive的过去式和过去分词 );(从…中)得到获得;源于;(从…中)提取
参考例句:
  • Many English words are derived from Latin and Greek. 英语很多词源出于拉丁文和希腊文。 来自《简明英汉词典》
  • He derived his enthusiasm for literature from his father. 他对文学的爱好是受他父亲的影响。 来自《简明英汉词典》
4 registrations d53ddf87a983739d49e0da0c1fa64925     
n.登记( registration的名词复数 );登记项目;登记(或注册、挂号)人数;(管风琴)音栓配合(法)
参考例句:
  • In addition to the check-in procedures, the room clerks are customarily responsible for recording advance registrations. 除了办理住宿手续外,客房登记员按惯例还负责预约登记。 来自辞典例句
  • Be the Elekta expert for products registrations in China. 成为在中国注册产品的医科达公司专家。 来自互联网
5 rosters 039aa80e18351f8a55d926fb6fc8c559     
n.花名册( roster的名词复数 );候选名单v.将(姓名)列入值勤名单( roster的第三人称单数 )
参考例句:
  • Teams have until Monday, Oct. 29 to set their rosters. 球队可以在下周一之前,即10月29确定他们的15人常规赛名单。 来自互联网
  • Rosters, R& R, FIFO or country-based lifestyle limiting your opportunities? 枯燥单调的生活方式限制了你的机会? 来自互联网
6 inventories 9d8e9044cc215163080743136fcb7fd5     
n.总结( inventory的名词复数 );细账;存货清单(或财产目录)的编制
参考例句:
  • In other cases, such as inventories, inputs and outputs are both continuous. 在另一些情况下,比如存货,其投入和产出都是持续不断的。
  • The store must clear its winter inventories by April 1st. 该店必须在4月1日前售清冬季存货。
7 compilations ce4f8f23fdb6a4149bf27a05e7a8aee1     
n.编辑,编写( compilation的名词复数 );编辑物
参考例句:
  • Introductory biology texts tend to be compilations of conclusions. 导论式的生物学教科书,多倾向于结论的汇编。 来自辞典例句
  • The original drafts were mainly chronicles and compilations of regulations. 初撰本主要以纪事本末体和典志体为主。 来自互联网
8 discrete 1Z5zn     
adj.个别的,分离的,不连续的
参考例句:
  • The picture consists of a lot of discrete spots of colour.这幅画由许多不相连的色点组成。
  • Most staple fibers are discrete,individual entities.大多数短纤维是不联系的单独实体。
9 confidential MOKzA     
adj.秘(机)密的,表示信任的,担任机密工作的
参考例句:
  • He refused to allow his secretary to handle confidential letters.他不让秘书处理机密文件。
  • We have a confidential exchange of views.我们推心置腹地交换意见。
10 confidentiality 7Y2yc     
n.秘而不宣,保密
参考例句:
  • They signed a confidentiality agreement. 他们签署了一份保守机密的协议。
  • Cryptography is the foundation of supporting authentication, integrality and confidentiality. 而密码学是支持认证、完整性和机密性机制的基础。
11 census arnz5     
n.(官方的)人口调查,人口普查
参考例句:
  • A census of population is taken every ten years.人口普查每10年进行一次。
  • The census is taken one time every four years in our country.我国每四年一次人口普查。
12 aggregating 0fe55a5efe451057100d17d440c89f32     
总计达…( aggregate的现在分词 ); 聚集,集合; (使)聚集
参考例句:
  • The thesis first promotes based Object Oriented Modeling method-Aggregating & Deriving Mothod. 本文首先提出了基于面向对象思想的建模方法——聚合派生法。
  • Multidimensional data cubes are composed of base cube and other cubes aggregating on base cube. 多维立方体由基本立方体和基本立方体的聚集产生的立方体组成。
13 deliberately Gulzvq     
adv.审慎地;蓄意地;故意地
参考例句:
  • The girl gave the show away deliberately.女孩故意泄露秘密。
  • They deliberately shifted off the argument.他们故意回避这个论点。
14 queries 5da7eb4247add5dbd5776c9c0b38460a     
n.问题( query的名词复数 );疑问;询问;问号v.质疑,对…表示疑问( query的第三人称单数 );询问
参考例句:
  • Our assistants will be happy to answer your queries. 我们的助理很乐意回答诸位的问题。
  • Her queries were rhetorical,and best ignored. 她的质问只不过是说说而已,最好不予理睬。 来自《简明英汉词典》
15 susceptible 4rrw7     
adj.过敏的,敏感的;易动感情的,易受感动的
参考例句:
  • Children are more susceptible than adults.孩子比成人易受感动。
  • We are all susceptible to advertising.我们都易受广告的影响。
16 scenarios f7c7eeee199dc0ef47fe322cc223be88     
n.[意]情节;剧本;事态;脚本
参考例句:
  • Further, graphite cores may be safer than non-graphite cores under some accident scenarios. 再者,根据一些事故解说,石墨堆芯可比非石墨堆芯更安全一些。 来自英汉非文学 - 环境法 - 环境法
  • Again, scenarios should make it clear which modes are acceptable to users in various contexts. 同样,我们可以运用场景剧本来搞清楚在不同情境下哪些模式可被用户接受。 来自About Face 3交互设计精髓
17 query iS4xJ     
n.疑问,问号,质问;vt.询问,表示怀疑
参考例句:
  • I query very much whether it is wise to act so hastily.我真怀疑如此操之过急地行动是否明智。
  • They raised a query on his sincerity.他们对他是否真诚提出质疑。
18 restriction jW8x0     
n.限制,约束
参考例句:
  • The park is open to the public without restriction.这个公园对公众开放,没有任何限制。
  • The 30 mph speed restriction applies in all built-up areas.每小时限速30英里适用于所有建筑物聚集区。
19 retrieves e07cf6bf3da2f0d490d60f9efc286e3f     
v.取回( retrieve的第三人称单数 );恢复;寻回;检索(储存的信息)
参考例句:
  • The mole comes in later, retrieves the item and packs it back in his gear. 鼹鼠随后到达,找回东西然后用他的传送装置返回。 来自电影对白
  • Retrieves the pitch of the current image, in bytes. 得到代表目前图像斜度的字节数。 来自互联网
20 retrieved 1f81ff822b0877397035890c32e35843     
v.取回( retrieve的过去式和过去分词 );恢复;寻回;检索(储存的信息)
参考例句:
  • Yesterday I retrieved the bag I left in the train. 昨天我取回了遗留在火车上的包。 来自《简明英汉词典》
  • He reached over and retrieved his jacket from the back seat. 他伸手从后座上取回了自己的夹克。 来自辞典例句
21 overlap tKixw     
v.重叠,与…交叠;n.重叠
参考例句:
  • The overlap between the jacket and the trousers is not good.夹克和裤子重叠的部分不好看。
  • Tiles overlap each other.屋瓦相互叠盖。
22 specified ZhezwZ     
adj.特定的
参考例句:
  • The architect specified oak for the wood trim. 那位建筑师指定用橡木做木饰条。
  • It is generated by some specified means. 这是由某些未加说明的方法产生的。
23 optimal zmDzhM     
adj.最适宜的;最理想的;最令人满意的
参考例句:
  • What is the optimal mix of private and public property rights in natural resources?私人和国家的自然资源产权的最适宜的组合是什么?
  • Optimal path planning is a key link for the sailing contest.帆船最优行驶路径规划是帆船比赛取胜的关键环节。
24 promising BkQzsk     
adj.有希望的,有前途的
参考例句:
  • The results of the experiments are very promising.实验的结果充满了希望。
  • We're trying to bring along one or two promising young swimmers.我们正设法培养出一两名有前途的年轻游泳选手。
25 evaluation onFxd     
n.估价,评价;赋值
参考例句:
  • I attempted an honest evaluation of my own life.我试图如实地评价我自己的一生。
  • The new scheme is still under evaluation.新方案还在评估阶段。
26 mechanisms d0db71d70348ef1c49f05f59097917b8     
n.机械( mechanism的名词复数 );机械装置;[生物学] 机制;机械作用
参考例句:
  • The research will provide direct insight into molecular mechanisms. 这项研究将使人能够直接地了解分子的机理。 来自《简明英汉词典》
  • He explained how the two mechanisms worked. 他解释这两台机械装置是如何工作的。 来自《简明英汉词典》
27 implement WcdzG     
n.(pl.)工具,器具;vt.实行,实施,执行
参考例句:
  • Don't undertake a project unless you can implement it.不要承担一项计划,除非你能完成这项计划。
  • The best implement for digging a garden is a spade.在花园里挖土的最好工具是铁锹。
28 criteria vafyC     
n.标准
参考例句:
  • The main criterion is value for money.主要的标准是钱要用得划算。
  • There are strict criteria for inclusion in the competition.参赛的标准很严格。
29 consistency IY2yT     
n.一贯性,前后一致,稳定性;(液体的)浓度
参考例句:
  • Your behaviour lacks consistency.你的行为缺乏一贯性。
  • We appreciate the consistency and stability in China and in Chinese politics.我们赞赏中国及其政策的连续性和稳定性。
TAG标签: data security information
发表评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
验证码:点击我更换图片